First published: Wed Jun 17 2020(Updated: )
Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.8>=8.9.0<8.9.1>=9.0.0<9.0.1 | |
composer/drupal/drupal | >=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.8>=8.9.0<8.9.1>=9.0.0<9.0.1 | |
Drupal Drupal | >=8.8.0<8.8.8 | |
Drupal Drupal | >=8.9.0<8.9.1 | |
Drupal Drupal | >=9.0.0<9.0.1 | |
composer/drupal/drupal | >=9.0.0<9.0.1 | 9.0.1 |
composer/drupal/drupal | >=8.9.0<8.9.1 | 8.9.1 |
composer/drupal/drupal | >=8.8.0<8.8.8 | 8.8.8 |
composer/drupal/core | >=9.0.0<9.0.1 | 9.0.1 |
composer/drupal/core | >=8.9.0<8.9.1 | 8.9.1 |
composer/drupal/core | >=8.8.0<8.8.8 | 8.8.8 |
>=8.8.0<8.8.8 | ||
>=8.9.0<8.9.1 | ||
>=9.0.0<9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Drupal Core vulnerability is CVE-2020-13665.
The severity of CVE-2020-13665 is critical with a CVSS score of 9.8.
Drupal Core 8.8.x versions prior to 8.8.8, 8.9.x versions prior to 8.9.1, and 9.0.x versions prior to 9.0.1 are affected by CVE-2020-13665.
The access bypass vulnerability in Drupal Core allows JSON:API to bypass access control permissions when JSON:API is in read/write mode.
To fix CVE-2020-13665, update your Drupal Core installation to version 8.8.8, 8.9.1, or 9.0.1 or apply the necessary patches provided by Drupal.